Threadlinqs IntelligenceStart free

Daily debrief · Tuesday2026-07-21

Daily Intelligence Briefing — Tuesday, July 21, 2026

7 critical11 high4 medium

On 2026-07-21, Threadlinqs published 19 new threat reports and updated 5, 7 rated critical and 11 high, spanning 222 MITRE ATT&CK techniques and 8 named threat actors. Coverage that day added 216 new detection rules and 710 extracted indicators.

New threats
195 updated
Critical / high
187 critical · 11 high
ATT&CK techniques
222Observed in the day’s reports
Threat actors
8Named in the reports
Indicators
710Count only · values are Red+
Detection rules
216New that day · rule text is Blue+

Edition date: · Last updated:

Summary & highlights

NULLZEREPTOOL: Telegram-Controlled Python DDoS and Multi-Function Attack Framework. ReHub: Russian-Language Cybercrime Marketplace Sponsoring DragonForce, LockBit, CHAOS, Anubis, The Gentlemen, and DevMan Ransomware Affiliate Programs. ASEC June 2026 Financial Sector Threat Roundup: Phishing-to-Infostealer Chains and Ransomware Dark Web Sales (LAPSUS$, MORPHEUS, Qilin).

Highlights

  • TL-2026-1582 — TELESHIM/MIXEDKEY/BINDCLOAK Multi-Stage Malware Chain Abuses Telegram Bot API for C2 Against Middle East Governments
  • TL-2026-1584 — Kali365 Device-Code Phishing-as-a-Service Hijacks Microsoft 365 and Google Workspace OAuth Tokens to Bypass MFA
  • TL-2026-1585 — "LegacyHive" Windows User Profile Service Zero-Day Allows Non-Admin Registry Hive Hijacking
  • TL-2026-1588 — Project CAV3RN / Cavern Manticore: Iran-Linked Modular Cyberespionage Framework Abuses Outlook Calendar (Microsoft Graph API) and DNS AAAA Records for C2 and Credential Recovery
  • TL-2026-1589 — SnappyClient RAT — C++ C2 Implant Delivered via HijackLoader (Operation Turb00 Part 3)

Theme of the day

Routine activity — no dominant theme emerged.

  • credential-theft
  • detection-engineering
  • data-exfiltration
  • cisa-kev
  • anti-analysis

Threats published

24 threat lines in the 2026-07-21 debrief, most severe first; entries marked (update) revise an earlier report. Each links to its full profile.

Techniques observed

222 MITRE ATT&CK and ATLAS techniques appear across the day’s reports.

Threat actors

8 named threat actors across the reports.

Nation-state attribution

  • Russia
  • China, Russia, Iran
  • Iran

Threat categories

  • MALWARE
  • THREAT_ACTOR
  • CAMPAIGN
  • THREAT_INTEL
  • SUPPLY_CHAIN
  • PHISHING
  • VULNERABILITY
  • DATA_BREACH
  • RANSOMWARE

Severity breakdown

  • critical7
  • high11
  • medium4
  • low0

Indicator & detection coverage

Counts only: the indicator values and detection rule text behind them are tiered.

710 indicators of compromise · Red and above. Compare plans
  • file 145
  • behavioral 144
  • network 144
  • entity 76
  • infrastructure 58
  • tool 49
  • malware 42
  • technique 25
  • package 14
  • vulnerability 13
216 new detection rules (100% of the day’s threats covered) · Blue and above. Compare plans